Windows: Zone.Identifier Alternate Data Stream Deleted by Uncommon Application
Alert on deletion of the Zone.Identifier ADS by an uncommon process on Windows.
- Product
- windows
- Category
- file_delete
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-09-04
- Updated
- 2026-07-31
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies deletion of the "Zone.Identifier" alternate data stream on a file when the deleting process image is not in a defined set of common browsers and Windows/PowerShell executables. Removing the Zone.Identifier ADS can help attackers reduce the effectiveness of content-marking controls used by applications such as Office. It relies on Windows file deletion telemetry that includes the target filename/path ending with ":Zone.Identifier" and the initiating process image.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows: Zone.Identifier Alternate Data Stream Deleted by Uncommon Application"
id: 2f56e404-f457-4068-adfe-4530c4867a2e
related:
- id: 7eac0a16-5832-4e81-865f-0268a6d19e4b
type: similar
- id: 3109530e-ab47-4cc6-a953-cac5ebcc93ae
type: derived
status: test
description: This rule identifies deletion of the "Zone.Identifier" alternate data stream on a file when the deleting process image is not in a defined set of common browsers and Windows/PowerShell executables. Removing the Zone.Identifier ADS can help attackers reduce the effectiveness of content-marking controls used by applications such as Office. It relies on Windows file deletion telemetry that includes the target filename/path ending with ":Zone.Identifier" and the initiating process image.
references:
- https://securityliterate.com/how-malware-abuses-the-zone-identifier-to-circumvent-detection-and-analysis/
- Internal Research
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_delete/file_delete_win_zone_identifier_ads_uncommon.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-09-04
modified: 2025-07-04
tags:
- attack.stealth
- attack.t1070.004
logsource:
product: windows
category: file_delete
detection:
selection:
TargetFilename|endswith: :Zone.Identifier
filter_main_generic:
Image:
- C:\Program Files\PowerShell\7-preview\pwsh.exe
- C:\Program Files\PowerShell\7\pwsh.exe
- C:\Windows\explorer.exe
- C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
- C:\Windows\SysWOW64\explorer.exe
- C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
filter_optional_browsers_chrome:
Image:
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- C:\Program Files\Google\Chrome\Application\chrome.exe
filter_optional_browsers_firefox:
Image:
- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
- C:\Program Files\Mozilla Firefox\firefox.exe
filter_optional_browsers_msedge:
Image:
- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
- C:\Program Files\Microsoft\Edge\Application\msedge.exe
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Other third party applications not listed.
level: medium
license: DRL-1.1